Feeds

Canada's privacy chief hails Microsoft's Seven Laws of Identity

On surviving the identity Big Bang

Internet Security Threat Report 2014

The Information and Privacy Commissioner of Ontario has published a plan for automated internet privacy that is backed by Microsoft. Dr Ann Cavoukian has called for programmers to embed privacy capabilities in software.

A Microsoft-led project to create an "identity layer" for the internet created Seven Laws of Identity, which Cavoukian has used as the basis for a paper calling for the laws to be embedded in software. The aim of the project is to help computer users to manage their own identity online.

"Just as the internet saw explosive growth as it sprang from the connection of different proprietary networks, an 'identity big bang' is expected to happen once an open, non-proprietary and universal method to connect identity systems and ensure user privacy is developed in accordance with privacy principles," said Cavoukian.

"Microsoft started a global privacy momentum. Already, there is a long and growing list of companies and individuals who now endorse the Seven Laws of Identity and are working towards developing identity systems that conform to them," she said.

Cavoukian argues that the latest generation of internet services, commonly called Web 2.0 and depending in many cases on personalisation, will create a demand for more information about users' identities. Users will need to know whether they can trust a site before handing over information, and the Seven Laws are designed to help users make that decision, said Cavoukian's office.

Microsoft has published its own guidelines on embedding privacy into software. "Privacy concerns are easy to understand in principle, but challenging to address in practice, particularly in the development of software," said Peter Cullen, chief privacy strategist at Microsoft. "Similar guidelines have helped Microsoft's developers better understand and address privacy issues, and we hope that by releasing a public version we can promote an ongoing industry dialogue on protecting privacy through consistent development practices."

The proposals for embedded privacy settings is not unlike the Platform for Privacy Preferences (P3P), a World Wide Web Consortium-developed automatic reader and sender of information about a website's privacy policies. It was launched in 2002.

Couvoukian said that another aim of the Seven Laws is to help users cut down on the degree to which data is shared and centralised.

"In the real world when we present a library card, for example, to check out a book, and present our passport to cross a national border we don’t expect these to be linked together," she said. "Nor is the access card we use to enter our office the same as the transit pass we use to board a bus. In the physical world, different transactions require different identity credentials, but they need not be linked together. It should be no different in the online environment."

Copyright © 2006, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

Related links

Dr Cavoukian's white paper (24-page / 271KB PDF)
Microsoft's paper on The Laws of Identity

Top 5 reasons to deploy VMware with Tegile

More from The Register

next story
Webcam hacker pervs in MASS HOME INVASION
You thought you were all alone? Nope – change your password, says ICO
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Meet OneRNG: a fully-open entropy generator for a paranoid age
Kiwis to seek random investors for crowd-funded randomiser
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
The Heartbleed Bug: how to protect your business with Symantec
What happens when the next Heartbleed (or worse) comes along, and what can you do to weather another chapter in an all-too-familiar string of debilitating attacks?
Top 5 reasons to deploy VMware with Tegile
Data demand and the rise of virtualization is challenging IT teams to deliver storage performance, scalability and capacity that can keep up, while maximizing efficiency.